Advisory Details

February 12th, 2026

Microsoft Exchange InterceptorSmtpAgent Reliance on Untrusted Inputs Security Feature Bypass Vulnerability

ZDI-26-082
ZDI-CAN-28410

CVE ID CVE-2026-21527
CVSS SCORE 5.3, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
AFFECTED VENDORS Microsoft
AFFECTED PRODUCTS Exchange
VULNERABILITY DETAILS

This vulnerability allows remote attackers to bypass a security feature on affected installations of Microsoft Exchange. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the InterceptorSmtpAgent class. The issue results from the improper handling of SMTP headers. An attacker can leverage this vulnerability to bypass a security feature offered by the product.

ADDITIONAL DETAILS Microsoft has issued an update to correct this vulnerability. More details can be found at:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21527
DISCLOSURE TIMELINE
  • 2025-11-14 - Vulnerability reported to vendor
  • 2026-02-12 - Coordinated public release of advisory
  • 2026-02-12 - Advisory Updated
CREDIT Vladislav Berghici of TrendAI Research
BACK TO ADVISORIES